Security services

What Should a Keyholding and Alarm Response Service Include?

The essential components of a managed keyholding and alarm response service for commercial premises.

Tornado FM Ltd Editorial Team5 min readPublished 14 July 2026
Security keyholder attending a commercial property following an alarm activation

A keyholding and alarm response service gives an authorised security provider responsibility for controlled keys or access information and a defined role when an alarm or attendance request is received. The service should protect the customer’s premises without transferring unclear risks to staff or leaving critical decisions unresolved.

BS 7984-1:2016 provides recommendations for the management, staffing and operation of keyholding and response services. The SIA also identifies keyholding as a licensable activity in relevant circumstances. Buyers should therefore examine licensing, key control, attendance procedures and reporting as a connected service.

Secure key and access-information control

The provider may hold physical keys, access cards, codes or other information that could enable entry. The customer should understand how these items are collected, identified, stored, accessed and returned.

  • Use a controlled reference that does not unnecessarily identify the premises.
  • Restrict access to authorised personnel.
  • Maintain an issue and return record.
  • Separate sensitive access information from obvious site-identifying details where practicable.
  • Set a process for lost, damaged, changed or compromised keys and credentials.
  • Review access information after tenant, staff, alarm or lock changes.

The contract should identify who owns replacement costs and what happens if the customer provides inaccurate or obsolete access information.

Accurate site and escalation information

Alarm response depends on the quality of the information available to the attending operative. A site information record should normally cover:

  • Full address, safe approach and authorised entry points.
  • Alarm zones, panel location and any available activation information.
  • Known hazards, restricted areas and lone-working concerns.
  • Nominated customer contacts in priority order.
  • Authority to reset, isolate, secure, wait for a contractor or leave the premises.
  • Police, fire, alarm receiving centre and specialist-contractor arrangements where applicable.
  • Animals, machinery, roof access, confined spaces or other material site risks.

Information should be reviewed periodically and after any operational change. An out-of-date contact list can turn a manageable activation into a prolonged incident.

A clearly defined activation process

The provider, customer and alarm receiving centre should understand how an attendance request is authorised and transmitted. The process should identify what information is provided, how receipt is confirmed and what happens if the first responder cannot attend.

Avoid relying on informal telephone arrangements that are not reflected in the contract or site instructions. The customer should know whether the service covers intruder alarms, fire alarms, environmental alarms, access problems or other attendance requests, and what exclusions apply.

Safe attendance at the premises

Alarm response frequently involves lone working, reduced visibility and uncertain conditions. HSE guidance requires employers to manage lone-working risks, train, supervise and monitor lone workers, keep in touch and respond to incidents.

  • Dynamic assessment of the approach and visible conditions.
  • Communication and welfare arrangements for the responding operative.
  • Restrictions on entering where there are signs of intrusion, fire, violence or another serious hazard.
  • Escalation to emergency services or the customer where the operative should not proceed alone.
  • Instructions for preserving potential evidence and avoiding unnecessary disturbance.

A security operative is not a police officer, firefighter, engineer or locksmith unless separately qualified and appointed. The service should define the responder’s role and limits.

External and internal checks

The attendance procedure should state what the operative is expected to inspect. This may include the perimeter, doors, windows, alarm panel, visible internal areas or the reported alarm zone where safe and authorised.

The objective is to establish what can reasonably be determined, take authorised action and provide a reliable report. It is not to search unsafe premises or guarantee that no incident has occurred.

Making the premises secure

The contract should define what the provider may do when damage or intrusion is found. Possible authorised actions may include closing an unsecured opening, arranging an approved emergency contractor, maintaining a presence while responsibility is transferred or contacting a nominated manager.

Spending limits, approval requirements and customer availability should be agreed in advance. Without them, an operative may be unable to protect the premises or may incur costs the customer did not authorise.

Reporting after every attendance

The customer should receive enough information to understand why attendance occurred, what was found and what remains outstanding.

  • Time the request was received and the operative was dispatched.
  • Arrival and departure times.
  • Condition of the perimeter and access points.
  • Alarm information and areas checked.
  • People contacted and instructions received.
  • Actions taken, including reset, isolation or contractor attendance.
  • Photographs where appropriate and lawful.
  • Outstanding faults, damage or recommended follow-up.

Service reviews and false-alarm patterns

Repeated activations should not become a routine attendance cost without investigation. Reports can identify recurring alarm zones, access failures, environmental causes or contact problems. The customer, alarm company and security provider should review patterns and allocate corrective action.

Questions to ask a keyholding provider

1. How are keys and access details identified, stored and audited?

2. Which SIA licences are required for the personnel delivering the service?

3. What information is required before the service can go live?

4. What hazards or circumstances prevent entry?

5. What authority does the operative have to spend money or instruct contractors?

6. How are lone-worker safety and communications managed?

7. What report will be issued after each attendance?

8. How are site details reviewed and updated?

A service built around the premises

Keyholding is not simply storing a key. It is a managed chain of authority, information, attendance, safety, action and reporting. The service should be designed around the premises and integrated with the customer’s alarm, access and emergency arrangements.

Tornado FM Ltd provides keyholding, alarm response, mobile patrols, lock and unlock services, vacant-property inspections, manned guarding, security assessments and concierge or reception security.

Request an initial discussion about your alarm, access and out-of-hours escalation requirements.

Related Tornado FM Ltd pages

Sources and further reading

  • British Standards Institution, BS 7984-1:2016 - General recommendations for keyholding and response services, published 30 April 2016; current and under review at access date.
  • Security Industry Authority, Find out if you need an SIA licence, guidance accessed 14 July 2026.
  • Health and Safety Executive, Lone working: Manage the risks of working alone, guidance accessed 14 July 2026.
  • Health and Safety Executive, Lone working: Training, supervision and monitoring, guidance accessed 14 July 2026.
  • British Standards Institution, BS 10800:2020 - Provision of security services. Code of practice, published 30 April 2020; current and under review at access date.

Source access date: 14 July 2026.

Chat with us on WhatsApp